<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firewall intercepts Virus between networks.  False Positive??? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-intercepts-virus-between-networks-false-positive/m-p/216093#M62614</link>
    <description>&lt;P&gt;Since when exactly do you have these in the logs? The signature was initially released by wildfire on 2018-05-21 and in normal threat updates on 2018-05-22. So depending when you have installed these updates, you probably have these alerts in the log since then... if this scanner runs continuously to do something.&lt;/P&gt;</description>
    <pubDate>Thu, 31 May 2018 12:32:05 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2018-05-31T12:32:05Z</dc:date>
    <item>
      <title>Firewall intercepts Virus between networks.  False Positive???</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-intercepts-virus-between-networks-false-positive/m-p/216068#M62602</link>
      <description>&lt;P&gt;Dear Palo Alto experts...,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have various systems in our LAN seperated by our Palo Alto firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the last 24 hours the firewall detected&amp;nbsp;2.7K times the virus&amp;nbsp; "Virus/Win32.WGeneric.rktkq"&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2018-05-31 10_39_51-FW-PA500-1.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15345i65668039B5EB1FC8/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2018-05-31 10_39_51-FW-PA500-1.png" alt="2018-05-31 10_39_51-FW-PA500-1.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2018-05-31 10_35_11-FW-PA500-1.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15346iF82A99CAB46C4FAB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2018-05-31 10_35_11-FW-PA500-1.png" alt="2018-05-31 10_35_11-FW-PA500-1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The systems are scanned for inventory by two programs. Spiceworks and PDQ inventory. The scan server is on one side of the firewall. The other servers are on the other side of the firewall.&lt;/P&gt;&lt;P&gt;The "Spiceworks" server has been scanned by our Kasperksy AntiVirus solution. No detections here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What could be causing this? And if it is a false positive, what would the next path forward to solve this problem?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any thoughts you might have are very welcome.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Remko&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 May 2018 08:46:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-intercepts-virus-between-networks-false-positive/m-p/216068#M62602</guid>
      <dc:creator>Indorama_Ventures</dc:creator>
      <dc:date>2018-05-31T08:46:09Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall intercepts Virus between networks.  False Positive???</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-intercepts-virus-between-networks-false-positive/m-p/216077#M62603</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/45031"&gt;@Indorama_Ventures&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Configure the firewall to gather a PCAP for the threat.&amp;nbsp; Then you can send the PCAP to TAC for analysis.&lt;/P&gt;
&lt;P&gt;If it's a false positive then likely a content update will fix it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;</description>
      <pubDate>Thu, 31 May 2018 09:16:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-intercepts-virus-between-networks-false-positive/m-p/216077#M62603</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2018-05-31T09:16:41Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall intercepts Virus between networks.  False Positive???</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-intercepts-virus-between-networks-false-positive/m-p/216078#M62604</link>
      <description>&lt;P&gt;Thanks... My apologies for being a bit blond here.. Bit of a newbie I guess. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;How would I go about sending the PCAP to TAC for analysis.&lt;/P&gt;&lt;P&gt;Never done this. Have no idea were to go and where to begin.&lt;/P&gt;</description>
      <pubDate>Thu, 31 May 2018 09:25:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-intercepts-virus-between-networks-false-positive/m-p/216078#M62604</guid>
      <dc:creator>Indorama_Ventures</dc:creator>
      <dc:date>2018-05-31T09:25:16Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall intercepts Virus between networks.  False Positive???</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-intercepts-virus-between-networks-false-positive/m-p/216080#M62605</link>
      <description>&lt;P&gt;I may have found something&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/Tips-amp-Tricks-Enable-Packet-Captures-on-Security-Profiles/ta-p/56449" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/Tips-amp-Tricks-Enable-Packet-Captures-on-Security-Profiles/ta-p/56449&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 31 May 2018 09:33:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-intercepts-virus-between-networks-false-positive/m-p/216080#M62605</guid>
      <dc:creator>Indorama_Ventures</dc:creator>
      <dc:date>2018-05-31T09:33:22Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall intercepts Virus between networks.  False Positive???</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-intercepts-virus-between-networks-false-positive/m-p/216081#M62606</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/45031"&gt;@Indorama_Ventures&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Enable packet capture in your Antivirus threat profile :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="2018-05-31_11-29-35.jpg" style="width: 638px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15347iBC04A3B98BAF10E2/image-dimensions/638x404?v=v2" width="638" height="404" role="button" title="2018-05-31_11-29-35.jpg" alt="2018-05-31_11-29-35.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This setting will create a PCAP that you can download for analysis on the Monitor &amp;gt; Threat log page.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 May 2018 09:34:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-intercepts-virus-between-networks-false-positive/m-p/216081#M62606</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2018-05-31T09:34:02Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall intercepts Virus between networks.  False Positive???</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-intercepts-virus-between-networks-false-positive/m-p/216083#M62608</link>
      <description>&lt;P&gt;I got my self a PCAP file. Thanks for pointing me in the right direction.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now need to find where to upload it for analysis.&lt;/P&gt;&lt;P&gt;Not been able to find this yet.&lt;/P&gt;&lt;P&gt;I noticed I can also exclude this particular finding but perhaps better to wait for the verdict of Palo Alto&lt;/P&gt;</description>
      <pubDate>Thu, 31 May 2018 09:53:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-intercepts-virus-between-networks-false-positive/m-p/216083#M62608</guid>
      <dc:creator>Indorama_Ventures</dc:creator>
      <dc:date>2018-05-31T09:53:06Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall intercepts Virus between networks.  False Positive???</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-intercepts-virus-between-networks-false-positive/m-p/216085#M62610</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/45031"&gt;@Indorama_Ventures&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For PCAP analysis,&amp;nbsp;you can create a support case and upload the file to the case.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;</description>
      <pubDate>Thu, 31 May 2018 11:18:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-intercepts-virus-between-networks-false-positive/m-p/216085#M62610</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2018-05-31T11:18:26Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall intercepts Virus between networks.  False Positive???</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-intercepts-virus-between-networks-false-positive/m-p/216087#M62611</link>
      <description>&lt;P&gt;Thanks, it appears I need to go through a local reseller in the Netherlands. I cannot create a case directly. This is cumbersome for just submitting a sample.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for helping me out here. Much appreciated!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Remko&lt;/P&gt;</description>
      <pubDate>Thu, 31 May 2018 11:28:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-intercepts-virus-between-networks-false-positive/m-p/216087#M62611</guid>
      <dc:creator>Indorama_Ventures</dc:creator>
      <dc:date>2018-05-31T11:28:10Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall intercepts Virus between networks.  False Positive???</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-intercepts-virus-between-networks-false-positive/m-p/216090#M62612</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/45031"&gt;@Indorama_Ventures&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have a wildfire subscription? In yes, you could upload the proplematic executable (as it looks like in your logs the virus is detected the smb transfer of this executable) to wildfire as it will maybe show malicious (this signature was initially created by wildfire). Then you could report an incorrect verdict there without the need to create a case at your reseller.&lt;/P&gt;&lt;P&gt;But the "best" is probably still if you create a case at your reseller (and ask for premium support at next renewal so you will be able to create cases directly &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Remo&lt;/P&gt;</description>
      <pubDate>Thu, 31 May 2018 12:14:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-intercepts-virus-between-networks-false-positive/m-p/216090#M62612</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-05-31T12:14:38Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall intercepts Virus between networks.  False Positive???</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-intercepts-virus-between-networks-false-positive/m-p/216092#M62613</link>
      <description>&lt;P&gt;Yes we do.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The file (PDQInventoryScanner.exe) as shown in the screenshot is classified as benign. So not sure why it is triggered.&lt;/P&gt;&lt;P&gt;In the screenshot&amp;nbsp; it also shows certain URL's as the same virus.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Most likely the inventory scanner also checks cloud services for things like warrenty, etc.&lt;/P&gt;&lt;P&gt;I just do not understand why I have all of a sudden 2.7 K of virusses detected &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have submitted a case now with the local reseller.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will keep you posted...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 May 2018 12:22:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-intercepts-virus-between-networks-false-positive/m-p/216092#M62613</guid>
      <dc:creator>Indorama_Ventures</dc:creator>
      <dc:date>2018-05-31T12:22:52Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall intercepts Virus between networks.  False Positive???</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-intercepts-virus-between-networks-false-positive/m-p/216093#M62614</link>
      <description>&lt;P&gt;Since when exactly do you have these in the logs? The signature was initially released by wildfire on 2018-05-21 and in normal threat updates on 2018-05-22. So depending when you have installed these updates, you probably have these alerts in the log since then... if this scanner runs continuously to do something.&lt;/P&gt;</description>
      <pubDate>Thu, 31 May 2018 12:32:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-intercepts-virus-between-networks-false-positive/m-p/216093#M62614</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-05-31T12:32:05Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall intercepts Virus between networks.  False Positive???</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-intercepts-virus-between-networks-false-positive/m-p/216097#M62616</link>
      <description>&lt;P&gt;I started noticing these warnings yesterday. Prior to this, this particular "virus" was not found.&lt;/P&gt;&lt;P&gt;The report runs at night for the last 24 hours.&lt;/P&gt;&lt;P&gt;Yesterday the count was 1973.&amp;nbsp;&lt;/P&gt;&lt;P&gt;For today (last&amp;nbsp;24 hours ) the count is 2040&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is hard to tell when exactly a scan is triggered. When the scan is &amp;gt; 7 days old. When a new application is installed a scanned is performed, etc.&lt;/P&gt;&lt;P&gt;Strange thing is that is also triggers on URL's&lt;/P&gt;&lt;P&gt;I am not sure why I am seeing these messages?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2018-05-31 14_49_42-FW-PA500-1.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15348iA54A51B8460F1D55/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2018-05-31 14_49_42-FW-PA500-1.png" alt="2018-05-31 14_49_42-FW-PA500-1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 May 2018 12:52:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-intercepts-virus-between-networks-false-positive/m-p/216097#M62616</guid>
      <dc:creator>Indorama_Ventures</dc:creator>
      <dc:date>2018-05-31T12:52:07Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall intercepts Virus between networks.  False Positive???</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-intercepts-virus-between-networks-false-positive/m-p/216108#M62620</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/45031"&gt;@Indorama_Ventures&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Make sure that you also add a packet capture of one of these logs (SMB traffic with an URL as filename) to the case. This either is a very special attack in your network or - probably more likely - a bug.&lt;/P&gt;</description>
      <pubDate>Thu, 31 May 2018 13:53:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-intercepts-virus-between-networks-false-positive/m-p/216108#M62620</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-05-31T13:53:20Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall intercepts Virus between networks.  False Positive???</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-intercepts-virus-between-networks-false-positive/m-p/216895#M62784</link>
      <description>&lt;P&gt;We also have this very same problem.&amp;nbsp; Also running PDQ Inventory and Spiceworks.&amp;nbsp; Do we need to upload a packet capture too?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Leo&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jun 2018 19:53:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-intercepts-virus-between-networks-false-positive/m-p/216895#M62784</guid>
      <dc:creator>Leo_Dittemore</dc:creator>
      <dc:date>2018-06-06T19:53:57Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall intercepts Virus between networks.  False Positive???</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-intercepts-virus-between-networks-false-positive/m-p/216936#M62789</link>
      <description>&lt;P&gt;I do not believe you do. This is the latest reply from Palo Alto&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;we've had a wave of few days last month where our static analysis caused a number of false positives due to an artifact that wasn't such a sure indicator of compromise yet it has had high value in our detectors; once we reviewed that IOC and adjusted it's weight in the static analysis algorithm, everything was fixed (regarding high false-positive rate). However, we still have few hashes to fix verdict on (such as few of those you shared).&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;I reviewed all the samples and they were flipped due to overly aggressive IOC weight.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jun 2018 06:19:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-intercepts-virus-between-networks-false-positive/m-p/216936#M62789</guid>
      <dc:creator>Indorama_Ventures</dc:creator>
      <dc:date>2018-06-07T06:19:02Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall intercepts Virus between networks.  False Positive???</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-intercepts-virus-between-networks-false-positive/m-p/216946#M62791</link>
      <description>&lt;P&gt;Leo,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We noticed that an upgrade was available of PDQ inventory. After the upgrade (release 3) the virus detections disappeared.&lt;/P&gt;&lt;P&gt;I have also informed PDQ/Admin Arsenal about our findings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Remko&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jun 2018 07:04:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-intercepts-virus-between-networks-false-positive/m-p/216946#M62791</guid>
      <dc:creator>Indorama_Ventures</dc:creator>
      <dc:date>2018-06-07T07:04:58Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall intercepts Virus between networks.  False Positive???</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-intercepts-virus-between-networks-false-positive/m-p/217104#M62827</link>
      <description>&lt;P&gt;I asked the PDQ team to update their application.&amp;nbsp; The firewall team also also tells me that a signature update released yesterday corrected this.&amp;nbsp; No alerts so far today.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;leo&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jun 2018 21:08:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-intercepts-virus-between-networks-false-positive/m-p/217104#M62827</guid>
      <dc:creator>Leo_Dittemore</dc:creator>
      <dc:date>2018-06-07T21:08:41Z</dc:date>
    </item>
  </channel>
</rss>

